Why post-quantum
What quantum-resistant signatures protect on Quantus, and where the limits are.
The problem
Most blockchains sign transactions with elliptic-curve schemes (ECDSA, Ed25519). A large enough quantum computer running Shor's algorithm could derive a private key from its public key, and so spend from any account whose public key is known. On most chains, that is every account that has ever sent a transaction.
Nobody can say when such a machine will exist. But a blockchain is a permanent public record: keys exposed today stay exposed.
What Quantus does
Quantus signs every transaction with ML-DSA-87, the highest security level of ML-DSA, the lattice-based signature scheme standardized by NIST in FIPS 204. No known quantum algorithm breaks it.
Qlyphs Wallet creates ML-DSA-87 accounts with the official Quantus SDK. Your keys are derived from
a 24-word recovery phrase (BIP-39) on the path m/44'/189189'/0'/0'/0', so the same phrase opens
the same account in any Quantus wallet that uses this path.
Hashes, too
Signatures are not the only thing a quantum computer threatens. Grover's algorithm speeds up the search for hash collisions and preimages, roughly halving a hash function's security in bits. The proofs Qlyphs witnesses sign are built with SHA-512, which keeps a very wide margin even halved.
What it does not cover
Post-quantum signatures protect your account on the chain. They do not make everything around it post-quantum:
- Your device. Malware on your computer can read what you type, including your password.
- The connection. Websites, including keys.qlyphs.com, are served over standard HTTPS.
- Updates. Browser stores sign extension updates with classical cryptography.
- Other chains. Assets and wallets on other blockchains use their own, mostly classical, signatures.
Post-quantum does not mean unhackable. Your recovery phrase is still the key to everything: keep it offline and never share it.